CompTIA SecurityX (CAS-005)Security EngineeringHard

A security architect is evaluating different key management strategies for an organization's cryptographic operations. The organization requires a solution that offers the highest level of assurance for protecting cryptographic keys, especially master keys, against both logical and physical attacks. Which key management solution offers this level of protection?

  1. ASoftware-based Key Management System (KMS)
  2. BEncrypted disk storage for keys
  3. CHardware Security Module (HSM)
  4. DCloud-based Key Management Service (KMS) without dedicated hardware
Show answer & explanation

Correct answer: C. Hardware Security Module (HSM)

Hardware Security Modules (HSMs) are dedicated physical computing devices that safeguard and manage digital keys, perform encryption and decryption functions, and provide a secure, tamper-resistant environment for cryptographic operations. They offer the highest level of assurance against both logical and physical attacks.

Why the other options are wrong

  • A. Software-based KMS solutions are vulnerable to attacks on the underlying operating system or application, offering less protection than hardware-based solutions.
  • B. Encrypting keys on disk still leaves them vulnerable if the encryption key for the disk or the operating system is compromised, and does not protect against physical tampering.
  • D. While cloud KMS offerings provide security, unless explicitly backed by dedicated HSMs (which is often an option), they may not offer the same level of tamper-resistance as on-premises HSMs.

Hardware Security Module (HSM)

A physical computing device that safeguards and manages digital keys, performs cryptographic functions, and provides a secure, tamper-resistant environment.

  • Provides highest assurance for key protection.
  • Tamper-resistant physical device.
  • Generates, stores, and protects cryptographic keys.

Memory trick: HSMs are the fortress for your cryptographic keys.

More Security Engineering questions